Converting from FIPS-140 to normal mode
Converting BMC Atrium Single Sign-On to operate in normal mode, (for example, without FIPS-140 cryptography) is the same process as converting the server to FIPS-140 mode, except the Java Virtual Machine (JVM) does not need to modified prior to triggering the conversion.
To convert to normal mode
- Shut down all integrated products.
If possible, use a firewall to block external access to BMC Atrium Single Sign-On. - Log on the Administrator console.
- Navigate to Configuration > Servers and Sites > <hostName> link > Security > Federal Information Processing Standards
In this case, the <hostName> link is a hyperlink similar to:
https://sample.bmc.com:8443/atriumsso - De-select FIPS Mode.
To commit the change, click Save.
This process usually takes around 10 to 20 seconds, depending upon the computer hardware.
Ensure that a successful conversion message is posted.
- Restore the original encryption files and non-FIPS140 library.
- Stop the BMC Atrium Single Sign-On server.
- Restore the strong encryption file.
- Restore the non-FIPS library.
- Restart BMC Atrium Single Sign-On.
- Verify that the server is properly operating in normal mode by viewing the BMC Atrium Single Sign-On log file (for example, atsso.0.log )
Reconfigure integrated products to operate in normal mode.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*